Options reference
selfhost.enable
Whether to enable home-server services.
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.apps.bazarr.enable
Whether to enable the first-party Bazarr app (subtitle automation; wiring + reconcile, no providers).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.apps.bazarr.apiKeyFile
Path to Bazarr’s generated API key.
Type: string (read only)
Default: the generated API-key secret path
Declared by:
selfhost.apps.bazarr.configureAfter
Extra units the reconcile must start after and want — Bazarr connection-tests the *arrs it is given.
Type: list of string
Default:
[ ]
Example:
[
"sonarr.service"
]
Declared by:
selfhost.apps.bazarr.dataDir
Bazarr state directory (config.yaml, database, logs).
Type: string
Default:
"/var/lib/bazarr"
Declared by:
selfhost.apps.bazarr.defaultProfile
Profile name applied to newly-added series and movies. Null leaves new media unassigned (nothing is fetched for it).
Type: null or string
Default:
null
Declared by:
selfhost.apps.bazarr.exporterPort
exportarr listen port (localhost) for Bazarr metrics.
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
9712
Declared by:
selfhost.apps.bazarr.languageProfiles
Language profiles to ensure. Which languages to want is taste, so the framework ships none — with no profile Bazarr downloads nothing. The posted list is authoritative: a profile removed here is removed from Bazarr.
Type: list of (submodule)
Default:
[ ]
Example:
[ { name = "English"; languages = [ "en" ]; cutoff = "en"; } ]
Declared by:
selfhost.apps.bazarr.languageProfiles.*.cutoff
Language that ends the search once found; null keeps searching for all of them.
Type: null or string
Default:
null
Declared by:
selfhost.apps.bazarr.languageProfiles.*.languages
Two-letter language codes to search for, in priority order.
Type: list of string
Default:
[ ]
Declared by:
selfhost.apps.bazarr.languageProfiles.*.name
Profile name.
Type: string
Declared by:
selfhost.apps.bazarr.port
Bazarr listen port (localhost, behind ingress).
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
6767
Declared by:
selfhost.apps.bazarr.radarr
Radarr to pull the movie library from. Null = Bazarr handles no movies.
Type: null or (submodule)
Default:
null
Declared by:
selfhost.apps.bazarr.radarr.apiKeyFile
Path to Radarr’s API key — typically apps.radarr.apiKeyFile.
Type: string
Declared by:
selfhost.apps.bazarr.radarr.baseUrl
Radarr URL base.
Type: string
Default:
"/"
Declared by:
selfhost.apps.bazarr.radarr.host
Radarr host reachable from Bazarr.
Type: string
Default:
"127.0.0.1"
Declared by:
selfhost.apps.bazarr.radarr.port
Radarr port.
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
7878
Declared by:
selfhost.apps.bazarr.secretSettings
Settings whose values are read from a file at reconcile time, as "<section>.<key>" = "/path/to/secret". For provider credentials.
Type: attribute set of string
Default:
{ }
Example:
{ "someprovider.password" = "/run/secrets/someprovider-password"; }
Declared by:
selfhost.apps.bazarr.settings
Freeform config.yaml sections merged into the reconcile, as <section>.<key>. This is the seam
for acquisition config: enabled providers and their per-provider options. Values that are secrets
belong in secretSettings, not here — this lands in the world-readable Nix store.
Type: attribute set of attribute set of anything
Default:
{ }
Example:
{ general.enabled_providers = [ "someprovider" ]; }
Declared by:
selfhost.apps.bazarr.sonarr
Sonarr to pull the series library from. Null = Bazarr handles no TV.
Type: null or (submodule)
Default:
null
Declared by:
selfhost.apps.bazarr.sonarr.apiKeyFile
Path to Sonarr’s API key — typically apps.sonarr.apiKeyFile.
Type: string
Declared by:
selfhost.apps.bazarr.sonarr.baseUrl
Sonarr URL base.
Type: string
Default:
"/"
Declared by:
selfhost.apps.bazarr.sonarr.host
Sonarr host reachable from Bazarr.
Type: string
Default:
"127.0.0.1"
Declared by:
selfhost.apps.bazarr.sonarr.port
Sonarr port.
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
8989
Declared by:
selfhost.apps.bentopdf.enable
Whether to enable the first-party BentoPDF app (static, client-side PDF toolkit).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.apps.desec.enable
Whether to enable deSEC dynamic DNS updates.
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.apps.desec.domains
Hostnames to keep pointed at the current public IP.
Type: non-empty (list of string)
Example:
[
"squirrel-plaza.dedyn.io"
]
Declared by:
selfhost.apps.desec.interval
Refresh period (systemd time span); a boot-time update also runs.
Type: string
Default:
"30min"
Declared by:
selfhost.apps.desec.tokenFile
File holding a deSEC API token authorized for domains.
Type: string
Declared by:
selfhost.apps.filebrowser.enable
Whether to enable the first-party FileBrowser app (per-user proxy-auth file sharing).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.apps.filebrowser.enableSelfhostIntegration
Derive FileBrowser users and per-user SMB binds from selfhost.users grants and register behind selfhost forwardAuth. Turn off to run the app but wire users, storage and auth yourself.
Type: boolean
Default:
true
Declared by:
selfhost.apps.gitea.enable
Whether to enable the first-party Gitea app (git server with OIDC login).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.apps.gitea.serviceAccounts
Non-human Gitea accounts (CI/bots), provisioned via the gitea CLI.
Type: attribute set of (submodule)
Default:
{ }
Declared by:
selfhost.apps.gitea.serviceAccounts.<name>.enable
Whether to enable this non-UI Gitea account.
Type: boolean
Default:
true
Example:
true
Declared by:
selfhost.apps.gitea.serviceAccounts.<name>.sshKeys
SSH keys for git-over-SSH; registered via the admin API on account creation.
Type: list of (submodule)
Default:
[ ]
Declared by:
selfhost.apps.gitea.serviceAccounts.<name>.sshKeys.*.key
Public key in authorized_keys format.
Type: string
Declared by:
selfhost.apps.gitea.serviceAccounts.<name>.sshKeys.*.readOnly
Register as a read-only (deploy) key.
Type: boolean
Default:
false
Declared by:
selfhost.apps.gitea.ssh.enable
Whether to enable Gitea’s built-in SSH server for git-over-SSH (off by default — exposes a TCP port; HTTPS git works without it).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.apps.gitea.ssh.openFirewall
Whether to enable opening the SSH port in the firewall (all interfaces); leave off to scope it yourself.
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.apps.gitea.ssh.port
Listen port for the built-in SSH server.
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
2222
Declared by:
selfhost.apps.homepage.enable
Whether to enable the first-party homepage dashboard app (gethomepage).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.apps.homepage.port
homepage listen port (localhost, behind ingress).
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
3001
Declared by:
selfhost.apps.immich.enable
Whether to enable the first-party Immich app (photo and video library).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.apps.jellyfin.enable
Whether to enable the first-party Jellyfin app (media server).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.apps.jellyfin.branding
Fields merged into Jellyfin’s branding configuration. Merged, not replaced, so a login disclaimer owned by an SSO plugin survives.
Type: attribute set of anything
Default:
{ }
Declared by:
selfhost.apps.jellyfin.defaultPolicy
Policy fields applied to every account, under each user’s own policy. The baseline most deployments want the same for everyone.
Type: attribute set of anything
Default:
{ }
Example:
{
EnableSubtitleManagement = true;
}
Declared by:
selfhost.apps.jellyfin.encoding
EncodingOptions fields, merged onto what Jellyfin holds and applied through the API after startup, so anything not named here keeps its value.
services.jellyfin.hardwareAcceleration and services.jellyfin.transcoding cover part of the same
ground by writing encoding.xml directly. Use one or the other, never both: together the file
always differs from the generated template, and each restart leaves another
encoding.xml.backup-<timestamp> behind.
Unknown keys are dropped silently, since Jellyfin ignores properties it does not recognise.
Type: attribute set of anything
Default:
{ }
Example:
{
TonemappingAlgorithm = "bt2390";
}
Declared by:
selfhost.apps.jellyfin.libraries
Libraries to create and keep pointed at their directories.
Type: list of (submodule)
Default:
[ ]
Declared by:
selfhost.apps.jellyfin.libraries.*.collectionType
Jellyfin collection type. Closed set, so a typo fails evaluation rather than the library create.
Type: one of “unknown”, “movies”, “tvshows”, “music”, “musicvideos”, “trailers”, “homevideos”, “boxsets”, “books”, “photos”, “livetv”, “playlists”, “folders”
Example:
"movies"
Declared by:
selfhost.apps.jellyfin.libraries.*.locations
Directories this library scans. Reconciled, so moving a path moves the library.
Type: list of string
Default:
[ ]
Declared by:
selfhost.apps.jellyfin.libraries.*.name
Library name in Jellyfin; also its reconcile identity, so renaming creates a second one.
Type: string
Declared by:
selfhost.apps.jellyfin.libraries.*.options
Fields merged into this library’s Jellyfin LibraryOptions, applied verbatim.
Type: attribute set of anything
Default:
{ }
Example:
{
EnableRealtimeMonitor = false;
}
Declared by:
selfhost.apps.jellyfin.serverName
Server name Jellyfin reports to clients.
Type: string
Default:
the service’s displayName
Declared by:
selfhost.apps.jellyfin.startup.metadataCountryCode
Metadata country code, applied once by the startup wizard.
Type: string
Default:
"US"
Declared by:
selfhost.apps.jellyfin.startup.preferredMetadataLanguage
Preferred metadata language, applied once by the startup wizard.
Type: string
Default:
"en"
Declared by:
selfhost.apps.jellyfin.startup.uiCulture
Interface culture, applied once by the startup wizard.
Type: string
Default:
"en-US"
Declared by:
selfhost.apps.jellyfin.trickplay
Fields merged into Jellyfin’s trickplay options.
Type: attribute set of anything
Default:
{ }
Declared by:
selfhost.apps.miniflux.enable
Whether to enable the first-party Miniflux app (RSS reader with OIDC login).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.apps.prowlarr.enable
Whether to enable the first-party Prowlarr app (indexer manager; wiring only, no indexers).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.apps.prowlarr.apiKeyFile
Path to Prowlarr’s generated API key, for the consumer indexer-sync reconciler.
Type: string (read only)
Default: the generated API-key secret path
Declared by:
selfhost.apps.prowlarr.exporterPort
exportarr listen port (localhost) for Prowlarr metrics. Each *arr needs its own — exportarr defaults them all to 9708.
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
9711
Declared by:
selfhost.apps.prowlarr.port
Prowlarr listen port (localhost, behind ingress).
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
9696
Declared by:
selfhost.apps.radarr.enable
Whether to enable the first-party Radarr app (media automation; ingress + auth + secrets wired, zero acquisition config).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.apps.radarr.apiKeyFile
Path to Radarr’s generated API key, for consumer reconcilers (e.g. Prowlarr sync, recyclarr).
Type: string (read only)
Default: the generated API-key secret path
Declared by:
selfhost.apps.radarr.configureAfter
Extra units the reconcile must start after and want. Radarr connection-tests a download client on save, so order this after the client’s service (e.g. your torrent/usenet daemon).
Type: list of string
Default:
[ ]
Example:
[
"transmission.service"
]
Declared by:
selfhost.apps.radarr.delayProfile
Optional default delay profile. Null = leave Radarr’s own default untouched. Carries the protocol preference — acquisition taste, no framework default.
Type: null or (submodule)
Default:
null
Declared by:
selfhost.apps.radarr.delayProfile.enableTorrent
This option has no description.
Type: boolean
Default:
true
Declared by:
selfhost.apps.radarr.delayProfile.enableUsenet
This option has no description.
Type: boolean
Default:
true
Declared by:
selfhost.apps.radarr.delayProfile.bypassIfHighestQuality
This option has no description.
Type: boolean
Default:
true
Declared by:
selfhost.apps.radarr.delayProfile.preferredProtocol
Protocol preference.
Type: one of “torrent”, “usenet”
Declared by:
selfhost.apps.radarr.delayProfile.torrentDelay
This option has no description.
Type: signed integer
Default:
0
Declared by:
selfhost.apps.radarr.delayProfile.usenetDelay
This option has no description.
Type: signed integer
Default:
0
Declared by:
selfhost.apps.radarr.downloadClients
Download clients to register. The framework applies them via the *arr schema; it ships none and assumes no protocol.
Type: list of (submodule)
Default:
[ ]
Declared by:
selfhost.apps.radarr.downloadClients.*.fields
Implementation-specific fields passed through to the client schema (host, port, category, …).
Type: attribute set of anything
Default:
{ }
Declared by:
selfhost.apps.radarr.downloadClients.*.implementation
The *arr download-client implementation (e.g. “Transmission”, “Sabnzbd”). No default — you choose.
Type: string
Declared by:
selfhost.apps.radarr.downloadClients.*.name
Client name in Radarr.
Type: string
Declared by:
selfhost.apps.radarr.downloadClients.*.protocol
Client protocol.
Type: one of “torrent”, “usenet”
Declared by:
selfhost.apps.radarr.exporterPort
exportarr listen port (localhost) for Radarr metrics. Each *arr needs its own — exportarr defaults them all to 9708.
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
9710
Declared by:
selfhost.apps.radarr.notifyOnImport
Publish a notification when an item is imported or upgraded. Turn this off when something downstream already tells people content arrived (a request manager, for example) — otherwise one arrival produces two messages describing the same thing. The failure events (health checks, manual interaction required) are always published and are not affected by this.
Type: boolean
Default:
true
Declared by:
selfhost.apps.radarr.port
Radarr listen port (localhost, behind ingress).
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
7878
Declared by:
selfhost.apps.radarr.rootFolders
Root library folders to ensure. Paths only — storage/protocol-agnostic.
Type: list of (submodule)
Default:
[ ]
Declared by:
selfhost.apps.radarr.rootFolders.*.defaultQualityProfile
Name of a quality profile (consumer/recyclarr-managed) to seed as this folder’s default; null = none.
Type: null or string
Default:
null
Declared by:
selfhost.apps.radarr.rootFolders.*.path
Library path (must exist on disk; typically a selfhost storage mount).
Type: string
Declared by:
selfhost.apps.radicale.enable
Whether to enable the first-party Radicale app (CalDAV/CardDAV server).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.apps.radicale.enableSelfhostIntegration
Derive Radicale’s htpasswd users from selfhost.users grants. Turn off to run Radicale but manage its htpasswd file yourself.
Type: boolean
Default:
true
Declared by:
selfhost.apps.sonarr.enable
Whether to enable the first-party Sonarr app (media automation; ingress + auth + secrets wired, zero acquisition config).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.apps.sonarr.apiKeyFile
Path to Sonarr’s generated API key, for consumer reconcilers (e.g. Prowlarr sync, recyclarr).
Type: string (read only)
Default: the generated API-key secret path
Declared by:
selfhost.apps.sonarr.configureAfter
Extra units the reconcile must start after and want. Sonarr connection-tests a download client on save, so order this after the client’s service (e.g. your torrent/usenet daemon).
Type: list of string
Default:
[ ]
Example:
[
"transmission.service"
]
Declared by:
selfhost.apps.sonarr.delayProfile
Optional default delay profile. Null = leave Sonarr’s own default untouched. Carries the protocol preference — acquisition taste, no framework default.
Type: null or (submodule)
Default:
null
Declared by:
selfhost.apps.sonarr.delayProfile.enableTorrent
This option has no description.
Type: boolean
Default:
true
Declared by:
selfhost.apps.sonarr.delayProfile.enableUsenet
This option has no description.
Type: boolean
Default:
true
Declared by:
selfhost.apps.sonarr.delayProfile.bypassIfHighestQuality
This option has no description.
Type: boolean
Default:
true
Declared by:
selfhost.apps.sonarr.delayProfile.preferredProtocol
Protocol preference.
Type: one of “torrent”, “usenet”
Declared by:
selfhost.apps.sonarr.delayProfile.torrentDelay
This option has no description.
Type: signed integer
Default:
0
Declared by:
selfhost.apps.sonarr.delayProfile.usenetDelay
This option has no description.
Type: signed integer
Default:
0
Declared by:
selfhost.apps.sonarr.downloadClients
Download clients to register. The framework applies them via the *arr schema; it ships none and assumes no protocol.
Type: list of (submodule)
Default:
[ ]
Declared by:
selfhost.apps.sonarr.downloadClients.*.fields
Implementation-specific fields passed through to the client schema (host, port, category, …).
Type: attribute set of anything
Default:
{ }
Declared by:
selfhost.apps.sonarr.downloadClients.*.implementation
The *arr download-client implementation (e.g. “Transmission”, “Sabnzbd”). No default — you choose.
Type: string
Declared by:
selfhost.apps.sonarr.downloadClients.*.name
Client name in Sonarr.
Type: string
Declared by:
selfhost.apps.sonarr.downloadClients.*.protocol
Client protocol.
Type: one of “torrent”, “usenet”
Declared by:
selfhost.apps.sonarr.exporterPort
exportarr listen port (localhost) for Sonarr metrics. Each *arr needs its own — exportarr defaults them all to 9708.
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
9709
Declared by:
selfhost.apps.sonarr.notifyOnImport
Publish a notification when an item is imported or upgraded. Turn this off when something downstream already tells people content arrived (a request manager, for example) — otherwise one arrival produces two messages describing the same thing. The failure events (health checks, manual interaction required) are always published and are not affected by this.
Type: boolean
Default:
true
Declared by:
selfhost.apps.sonarr.port
Sonarr listen port (localhost, behind ingress).
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
8989
Declared by:
selfhost.apps.sonarr.rootFolders
Root library folders to ensure. Paths only — storage/protocol-agnostic.
Type: list of (submodule)
Default:
[ ]
Declared by:
selfhost.apps.sonarr.rootFolders.*.defaultQualityProfile
Name of a quality profile (consumer/recyclarr-managed) to seed as this folder’s default; null = none.
Type: null or string
Default:
null
Declared by:
selfhost.apps.sonarr.rootFolders.*.path
Library path (must exist on disk; typically a selfhost storage mount).
Type: string
Declared by:
selfhost.apps.transmission.enable
Whether to enable the first-party Transmission app (torrent client).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.apps.wireguard.enable
Whether to enable WireGuard VPN server (interface, keys, user/device registry, client provisioning).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.apps.wireguard.address
Server address with CIDR (e.g. 10.100.0.1/24).
Type: string
Declared by:
selfhost.apps.wireguard.clientSubnet
Client address subnet (e.g. 10.100.0.0/24).
Type: string
Declared by:
selfhost.apps.wireguard.dns
DNS server pushed to clients.
Type: string
Declared by:
selfhost.apps.wireguard.endpoint
Public endpoint host/IP that clients dial.
Type: string
Declared by:
selfhost.apps.wireguard.exporterPort
Prometheus wireguard-exporter listen port (localhost).
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
9586
Declared by:
selfhost.apps.wireguard.interface
WireGuard interface name.
Type: string
Default:
"wg0"
Declared by:
selfhost.apps.wireguard.lanAccess.enable
Whether to enable opt-in nftables forwarding/NAT so clients reach the LAN (else clients reach only the server).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.apps.wireguard.lanAccess.masquerade
Whether to enable srcnat masquerade of client traffic into the LAN (enable only if the LAN lacks routes back to the client subnet).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.apps.wireguard.lanAccess.subnet
LAN subnet full-access clients may reach; added to their AllowedIPs and used as the masquerade destination. Required when lanAccess.enable.
Type: string
Declared by:
selfhost.apps.wireguard.listenPort
WireGuard UDP listen port (opened in the firewall).
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
51820
Declared by:
selfhost.apps.wireguard.name
Short identity prefix for client interface/device names (e.g. ‘bphenr’).
Type: string
Declared by:
selfhost.apps.wireguard.openFirewall
Open the WireGuard listen UDP port in the firewall.
Type: boolean
Default:
true
Declared by:
selfhost.apps.wireguard.peers
Derived per-device peers { name, device, ip, fullAccess, publicKey } for consumer firewall/routing rules.
Type: list of attribute set of anything (read only)
Default:
derived from users.*.services.wireguard
Declared by:
selfhost.auth.forwardAuth.active
Whether a forward-auth provider is active. Compose service defaults against this.
Type: boolean (read only)
Default:
true once a provider sets url
Declared by:
selfhost.auth.forwardAuth.path
Verify path appended to url for the ingress forward-auth middleware (e.g. /api/auth/traefik); set by the active provider.
Type: string
Default:
""
Declared by:
selfhost.auth.forwardAuth.tinyauth.enable
Whether to enable tinyauth forward-auth gateway (federates to the selfhost OIDC provider).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.auth.forwardAuth.tinyauth.port
tinyauth listen port (localhost, behind ingress).
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
3000
Declared by:
selfhost.auth.forwardAuth.url
Base URL of the forward-auth endpoint, set by the active provider and consumed by the ingress provider (null = no provider active).
Type: null or string
Default:
null
Declared by:
selfhost.auth.oidc.active
Whether an OIDC provider is active, set by the active provider. Compose service defaults against this.
Type: boolean
Default:
false
Declared by:
selfhost.auth.oidc.clients
Derived OIDC client configs keyed by service name (read-only)
Type: attribute set of raw value (read only)
Default:
{ }
Declared by:
selfhost.auth.oidc.credentials.dir
Base directory for OIDC credentials (persistent; see credentialsBaseDir).
Type: string (read only)
Default:
"/var/lib/homelab-oidc"
Declared by:
selfhost.auth.oidc.credentials.usersFile
JSON file mapping usernames to their OIDC provider user IDs
Type: string (read only)
Default:
"/var/lib/homelab-oidc/oidc-users.json"
Declared by:
selfhost.auth.oidc.pocket-id.enable
Whether to enable Pocket-ID OIDC implementation.
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.auth.oidc.pocket-id.port
Pocket-ID listen port (localhost, behind ingress).
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
8094
Declared by:
selfhost.auth.oidc.provider.apiKeyFile
Path to file containing provider API key
Type: string
Declared by:
selfhost.auth.oidc.provider.discoveryUrl
OIDC discovery document URL (derived from issuerUrl); for consumers that need the full well-known URL rather than the bare issuer.
Type: string (read only)
Default:
<issuerUrl>/.well-known/openid-configuration
Declared by:
selfhost.auth.oidc.provider.displayName
Display name of the OIDC provider (shown in UI)
Type: string
Declared by:
selfhost.auth.oidc.provider.internalName
Internal name for URLs and identifiers
Type: string
Declared by:
selfhost.auth.oidc.provider.issuerUrl
OIDC issuer URL (e.g. https://auth.example.com)
Type: string
Declared by:
selfhost.auth.oidc.provisionConfig
Provisioning config derived from OIDC-enabled users and services (read-only)
Type: raw value (read only)
Default:
{
groups = [
{
name = "admin";
}
{
name = "guests";
}
{
name = "users";
}
];
users = [ ];
}
Declared by:
selfhost.auth.oidc.rotation.enable
Whether to enable a timer that rotates all OIDC client secrets on a schedule.
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.auth.oidc.rotation.notifyTopic
selfhost.notify topic to alert on if a scheduled rotation fails (null = no alert).
Type: null or string
Default:
null
Declared by:
selfhost.auth.oidc.rotation.schedule
systemd OnCalendar expression for the rotation timer (default: weekly, Sunday 03:00).
Type: string
Default:
"Sun *-*-* 03:00:00"
Example:
"monthly"
Declared by:
selfhost.auth.oidc.systemd.baseProvisionUnit
Systemd unit for base OIDC provisioning (users/groups)
Type: null or string
Default:
null
Declared by:
selfhost.auth.oidc.systemd.clientProvisionUnitPrefix
Prefix for per-client provisioning unit names (provider sets this; e.g. ‘<provider>-provision-client-’ yields ‘<provider>-provision-client-<name>.service’).
Type: null or string
Default:
null
Declared by:
selfhost.backup.package
The rustic-manage package to use (shared by all targets).
Type: package
Declared by:
selfhost.backup.targets
Backup destinations. Each is an independent rustic pipeline with its own content, repository, retention, and schedule.
Type: attribute set of (submodule)
Default:
{ }
Declared by:
selfhost.backup.targets.<name>.backendCredentialsFile
Storage backend access credentials as a rustic secrets TOML ([repository.options]); symlinked to /etc/rustic/<name>-secrets.toml. Null for local-path repositories (no backend auth).
Type: null or string
Default:
null
Declared by:
selfhost.backup.targets.<name>.backupSchedule
systemd OnCalendar schedule for the backup timer.
Type: string
Default:
"*-*-* 03:00:00"
Declared by:
selfhost.backup.targets.<name>.bindings
Virtual backup path (key, must start with ‘/’) -> source path (value), mounted read-only into this target’s tree.
Type: attribute set of string
Default:
{ }
Example:
{
"/nas/notes" = "/mnt/nas/notes";
}
Declared by:
selfhost.backup.targets.<name>.globs
rustic include/exclude globs (‘!’ = exclude). Default excludes common NAS/sync/OS metadata.
Type: list of string
Default:
[
"!@eaDir"
"!.stfolder"
"!.stversions"
"!.Trash*"
"!@Recycle"
"!$RECYCLE.BIN"
"!.DS_Store"
"!Thumbs.db"
"!#snapshot"
"!#recycle"
"!.zfs"
]
Declared by:
selfhost.backup.targets.<name>.hooks
Standalone pre-backup hooks not tied to a registry service (e.g. GitHub), run for this target.
Type: attribute set of (submodule)
Default:
{ }
Declared by:
selfhost.backup.targets.<name>.hooks.<name>.package
Package providing a backup script. OUTPUT_DIR points to a fresh, empty directory for the hook’s output.
Type: package
Declared by:
selfhost.backup.targets.<name>.hooks.<name>.after
Systemd units this hook must run after (e.g. the service whose data it snapshots).
Type: list of string
Default:
[ ]
Declared by:
selfhost.backup.targets.<name>.passwordFile
rustic repository encryption password file.
Type: string
Declared by:
selfhost.backup.targets.<name>.repository
rustic repository string (e.g. ‘opendal:b2’).
Type: string
Declared by:
selfhost.backup.targets.<name>.retention
Snapshot retention policy (rustic forget keep-within-*).
Type: submodule
Declared by:
selfhost.backup.targets.<name>.retention.daily
How long to keep daily snapshots (rustic keep-within-daily; e.g. 7 days).
Type: string
Declared by:
selfhost.backup.targets.<name>.retention.monthly
How long to keep monthly snapshots (e.g. 1 year).
Type: string
Declared by:
selfhost.backup.targets.<name>.retention.weekly
How long to keep weekly snapshots (e.g. 1 month).
Type: string
Declared by:
selfhost.backup.targets.<name>.retention.yearly
How long to keep yearly snapshots (e.g. 2 years).
Type: string
Declared by:
selfhost.backup.targets.<name>.services
Registry services whose backup hook to run for this target (must declare services.<name>.backup.package).
Type: list of impossible (empty enum)
Default:
[ ]
Declared by:
selfhost.backup.targets.<name>.verifySchedule
systemd OnCalendar schedule for the verification timer.
Type: string
Default:
"Sun *-*-* 05:00:00"
Declared by:
selfhost.dashboards.generatedTiles
Service/external tiles keyed by integrations.homepage.group (read-only). The bundled apps.homepage renders these; otherwise read them into a dashboard you own and decide tabs/layout.
Type: attribute set of list of anything (read only)
Default:
{ }
Declared by:
selfhost.external
External services not managed by this host (shown on homepage dashboard via integrations.homepage)
Type: attribute set of (submodule)
Default:
{ }
Declared by:
selfhost.external.<name>.displayName
Human-readable name (defaults to attribute name)
Type: string
Default:
"‹name›"
Declared by:
selfhost.external.<name>.integrations.homepage
Homepage dashboard integration
Type: submodule
Default:
{ }
Declared by:
selfhost.external.<name>.integrations.homepage.enable
Whether to enable homepage entry for this service.
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.external.<name>.integrations.homepage.group
Free-form tile group this service belongs to; you map groups to tabs/layout in your dashboard.
Type: string
Default:
"Services"
Declared by:
selfhost.external.<name>.integrations.homepage.icon
Icon name from dashboard-icons (e.g. ‘miniflux.svg’)
Type: null or string
Default:
"‹name›.svg"
Declared by:
selfhost.external.<name>.integrations.homepage.settings
Extra homepage tile settings merged into the generated entry (e.g. a widget).
Type: attribute set
Default:
{ }
Declared by:
selfhost.external.<name>.meta.category
Canonical grouping key; a consumer surface (e.g. a landing page) groups services by this.
Type: null or string
Default:
null
Declared by:
selfhost.external.<name>.meta.description
Short description (nixpkgs meta.description).
Type: string
Declared by:
selfhost.external.<name>.meta.homepage
Upstream project homepage (nixpkgs meta.homepage).
Type: null or string
Default:
null
Declared by:
selfhost.external.<name>.name
Registry identifier (defaults to attribute name)
Type: string
Default:
"‹name›"
Declared by:
selfhost.external.<name>.url
Direct URL to the external service
Type: string
Declared by:
selfhost.groups.admin
Name of the admin group
Type: string
Default:
"admin"
Declared by:
selfhost.groups.guests
Name of the guests group
Type: string
Default:
"guests"
Declared by:
selfhost.groups.users
Name of the users group
Type: string
Default:
"users"
Declared by:
selfhost.ingress.acme.credentialsEnvFile
Path to an env file with the DNS provider’s credentials (e.g. CF_DNS_API_TOKEN). Provided by the host, e.g. via sops-nix.
Type: string
Declared by:
selfhost.ingress.acme.dnsProvider
DNS-01 challenge provider name for the ACME client (e.g. ‘cloudflare’)
Type: string
Declared by:
selfhost.ingress.acme.email
ACME account email for certificate registration
Type: string
Declared by:
selfhost.ingress.allowedInterfaces
Network interfaces to allow HTTP/HTTPS traffic on. If empty, allows on all interfaces (not recommended).
Type: list of string
Default:
[ ]
Declared by:
selfhost.ingress.domain
Base domain for publicly routed services (e.g. ‘home.example.com’). Required once any service enables ingress; a host that routes nothing may leave it null.
Type: null or string
Default:
null
Declared by:
selfhost.ingress.traefik.enable
Whether to enable Traefik reverse-proxy ingress implementation.
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.ingress.traefik.metricsPort
Port for Traefik’s Prometheus metrics endpoint (localhost only)
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
8082
Declared by:
selfhost.internal.listeningPorts.*.host
Listen address.
Type: string
Default:
"127.0.0.1"
Declared by:
selfhost.internal.listeningPorts.*.name
Owner identifier, shown in collision messages.
Type: string
Declared by:
selfhost.internal.listeningPorts.*.port
Listen port.
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Declared by:
selfhost.inventory
Registered services as use-case-agnostic facts (name, displayName, description, normalized access model, ingress, publicUrl, meta.homepage). Read-only; consumers decide presentation.
Type: list of (attribute set) (read only)
Default:
[ ]
Declared by:
selfhost.mail.from
Sender email address
Type: string
Declared by:
selfhost.mail.host
SMTP server hostname
Type: string
Declared by:
selfhost.mail.passwordFile
Path to file containing the SMTP password (typically a sops secret path)
Type: string
Declared by:
selfhost.mail.port
SMTP server port
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
587
Declared by:
selfhost.mail.tls
TLS mode for SMTP connection
Type: one of “none”, “starttls”, “tls”
Default:
"starttls"
Declared by:
selfhost.mail.user
SMTP authentication username
Type: string
Declared by:
selfhost.monitoring.enable
Whether to enable Prometheus monitoring (metrics, healthchecks, alert rules).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.monitoring.alertmanager.enable
Whether to enable Alertmanager alert delivery (routes fired alerts to notify).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.monitoring.alertmanager.port
Alertmanager listen port (localhost, behind ingress).
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
9093
Declared by:
selfhost.monitoring.blackboxPort
Blackbox-exporter listen port (localhost) for service healthchecks.
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
9116
Declared by:
selfhost.monitoring.prometheusPort
Prometheus listen port (localhost, behind ingress).
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
9090
Declared by:
selfhost.monitoring.retentionSize
Prometheus metrics retention size cap (the effective bound).
Type: string
Default:
"5GB"
Declared by:
selfhost.monitoring.retentionTime
Prometheus metrics retention time.
Type: string
Default:
"365d"
Declared by:
selfhost.monitoring.scopes
Monitoring scopes: infrastructure, hardware, and other non-service metric sources
Type: attribute set of (submodule)
Default:
{ }
Declared by:
selfhost.monitoring.scopes.<name>.enable
Whether to enable this monitoring scope.
Type: boolean
Default:
true
Example:
true
Declared by:
selfhost.monitoring.scopes.<name>.exporters
Prometheus exporter definitions merged into services.prometheus.exporters
Type: attribute set of anything
Default:
{ }
Declared by:
selfhost.monitoring.scopes.<name>.rules
Prometheus alert rule groups
Type: list of (attribute set)
Default:
[ ]
Declared by:
selfhost.monitoring.scopes.<name>.scrapeConfigs
Prometheus scrape configurations
Type: list of (attribute set)
Default:
[ ]
Declared by:
selfhost.monitoring.scopes.<name>.systemdOverrides
Systemd service overrides for monitoring-related units
Type: attribute set of anything
Default:
{ }
Declared by:
selfhost.monitoring.scrapeInterval
Global Prometheus scrape and evaluation interval.
Type: string
Default:
"60s"
Declared by:
selfhost.notify.package
send-notification implementation. Contract: send-notification --topic <t> --message <m> [--title <T>] [--priority <p>] [--tags <x>], reading NOTIFY_URL and NOTIFY_TOKEN_FILE from the env.
Type: package
Default:
pkgs.selfhost.send-notification
Declared by:
selfhost.notify.active
Whether a notify provider is active. Compose service defaults against this.
Type: boolean (read only)
Default:
true once a provider sets url
Declared by:
selfhost.notify.ntfy.enable
Whether to enable ntfy notification implementation (server + provisioning).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.notify.ntfy.port
ntfy listen port (localhost, behind ingress).
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Default:
2586
Declared by:
selfhost.notify.provisioningUnit
Systemd unit of the active provider that provisions publisher tokens; consumers that read a token via LoadCredential order after it. null = no provider, or a provider with no provisioning step.
Type: null or string
Default:
null
Declared by:
selfhost.notify.topics
Notification topics and their visibility (framework subsystems self-register their own homelab-* topics).
Type: attribute set of (submodule)
Default:
{ }
Declared by:
selfhost.notify.topics.<name>.public
Whether the topic can be read without authentication (grants everyone ro). Publishing always needs a per-service token, so this decides who can see the messages, not who can send them.
Type: boolean
Default:
false
Declared by:
selfhost.notify.url
Base URL of the notification endpoint, set by the active notify provider and consumed by send-notification (NOTIFY_URL); null = no provider active.
Type: null or string
Default:
null
Declared by:
selfhost.oidcPlaceholder
Opaque placeholder pair per OIDC client.
Type: attribute set of (submodule) (read only)
Default:
{ }
Declared by:
selfhost.oidcPlaceholder.<name>.id
This option has no description.
Type: string
Declared by:
selfhost.oidcPlaceholder.<name>.secret
This option has no description.
Type: string
Declared by:
selfhost.runtimePlaceholder
Opaque placeholder string per declared runtime secret.
Type: attribute set of string (read only)
Default:
{ }
Declared by:
selfhost.runtimeSecrets
Runtime-generated secret files (one-shot openssl rand).
Type: attribute set of (submodule)
Default:
{ }
Declared by:
selfhost.runtimeSecrets.<name>.bytes
Random bytes (hex-encoded; file is 2x chars).
Type: signed integer
Default:
32
Declared by:
selfhost.runtimeSecrets.<name>.generateOnce
Generate once, then never regenerate (supersedes regenerateIfMissing): a later loss is left absent and logged, not silently replaced — for data-bound secrets (e.g. an encryption key). To rotate deliberately, remove the secret together with the protected data.
Type: boolean
Default:
false
Declared by:
selfhost.runtimeSecrets.<name>.generateOnceGuard
Path to the data a generate-once secret protects (e.g. a service’s data dir). While it exists and is non-empty, a missing secret is left absent rather than regenerated. Required when generateOnce = true.
The unit that creates this path must be listed in restartUnits, which is what orders it after the
generator. Without that ordering it can populate the path first, and the guard then suppresses the
very first generation, permanently and silently.
Type: null or string
Default:
null
Declared by:
selfhost.runtimeSecrets.<name>.group
Unix group; defaults to owner’s primary group.
Type: null or string
Default:
null
Declared by:
selfhost.runtimeSecrets.<name>.mode
File mode (octal) of the secret file.
Type: string
Default:
"0400"
Declared by:
selfhost.runtimeSecrets.<name>.owner
Unix owner of the file.
Type: string
Default:
"root"
Declared by:
selfhost.runtimeSecrets.<name>.path
This option has no description.
Type: string (read only)
Default:
"/var/lib/homelab-secrets/‹name›"
Declared by:
selfhost.runtimeSecrets.<name>.regenerateIfMissing
Generate a new random value if the file is missing. When false (externally-synced secrets), the file is left absent and logged rather than aborting secret generation; consumers fail until it is restored.
Type: boolean
Default:
true
Declared by:
selfhost.runtimeSecrets.<name>.restartUnits
Units consuming this secret; wired requires+after on the generator (ordering only; values are persistent).
Type: list of string
Default:
[ ]
Declared by:
selfhost.runtimeSecretsDir
Persistent directory containing runtime-generated secret files. Include in backups.
Type: string (read only)
Default:
"/var/lib/homelab-secrets"
Declared by:
selfhost.runtimeTemplates
Templates rendered from runtime secrets and OIDC credentials.
Type: attribute set of (submodule)
Default:
{ }
Declared by:
selfhost.runtimeTemplates.<name>.content
Template body; reference secrets via runtimePlaceholder.<name> and OIDC creds via oidcPlaceholder.<client>.{id,secret}.
Type: strings concatenated with “\n”
Declared by:
selfhost.runtimeTemplates.<name>.group
Unix group; defaults to owner’s primary group.
Type: null or string
Default:
null
Declared by:
selfhost.runtimeTemplates.<name>.mode
File mode (octal) of the rendered file.
Type: string
Default:
"0400"
Declared by:
selfhost.runtimeTemplates.<name>.owner
Unix owner of the rendered file.
Type: string
Default:
"root"
Declared by:
selfhost.runtimeTemplates.<name>.path
Rendered output path (tmpfs; regenerated each boot).
Type: string
Default:
"/run/homelab-secrets/templates/‹name›"
Declared by:
selfhost.runtimeTemplates.<name>.restartUnits
Units restarted when the template body changes between deploys.
Type: list of string
Default:
[ ]
Declared by:
selfhost.services
Registry of selfhost services: routing, metadata, and integrations (HTTP ingress optional via ingress.enable).
Type: attribute set of (submodule)
Default:
{ }
Declared by:
selfhost.services.<name>.access.allowedGroups
Groups authorized to access this service (canonical groups or any a user is in). Empty means unrestricted (any authenticated user).
Type: list of (one of “admin”, “guests”, “users”)
Default:
[ ]
Declared by:
selfhost.services.<name>.backup.package
Package providing backup script. Use writeShellApplication with runtimeInputs for dependencies. OUTPUT_DIR is provided as an environment variable pointing to a fresh, empty directory for the hook’s output.
Type: null or package
Default:
null
Declared by:
selfhost.services.<name>.backup.after
Systemd services this backup hook requires and orders after.
Type: list of string
Default:
[ ]
Declared by:
selfhost.services.<name>.displayName
Human-readable name (defaults to attribute name)
Type: string
Default:
"‹name›"
Declared by:
selfhost.services.<name>.extraConfig
Consumer-owned per-service data with no first-class option (e.g. a landing-page tag); selfhost-nix never reads it. Co-located on the service entry instead of a parallel tree keyed by name. Read back at config.selfhost.services.<name>.extraConfig.
Type: open submodule of attribute set of anything
Default:
{ }
Declared by:
selfhost.services.<name>.forwardAuth.enable
Whether to enable ingress-level access control via the forward-auth gateway.
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.services.<name>.healthcheck.path
Path for health checks (used by monitoring and homepage)
Type: string
Default:
"/"
Declared by:
selfhost.services.<name>.healthcheck.probeModule
Blackbox exporter module for health probes. Use http_any for services that require authentication on all endpoints.
Type: one of “http_2xx”, “http_any”
Default:
"http_2xx"
Declared by:
selfhost.services.<name>.healthcheck.url
Full health check URL (derived from url and healthcheck path)
Type: string (read only)
Default:
<url><healthcheck.path>
Declared by:
selfhost.services.<name>.host
Hostname or IP where the service listens (local or remote)
Type: string
Default:
"127.0.0.1"
Declared by:
selfhost.services.<name>.ingress.enable
Whether to enable HTTP ingress route for this service.
Type: boolean
Default:
true
Example:
true
Declared by:
selfhost.services.<name>.integrations.homepage
Homepage dashboard integration
Type: submodule
Default:
{ }
Declared by:
selfhost.services.<name>.integrations.homepage.enable
Whether to enable homepage entry for this service.
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.services.<name>.integrations.homepage.group
Free-form tile group this service belongs to; you map groups to tabs/layout in your dashboard.
Type: string
Default:
"Services"
Declared by:
selfhost.services.<name>.integrations.homepage.icon
Icon name from dashboard-icons (e.g. ‘miniflux.svg’)
Type: null or string
Default:
"‹name›.svg"
Declared by:
selfhost.services.<name>.integrations.homepage.settings
Extra homepage tile settings merged into the generated entry (e.g. a widget).
Type: attribute set
Default:
{ }
Declared by:
selfhost.services.<name>.integrations.monitoring.enable
Whether to enable monitoring for this service.
Type: boolean
Default:
follows selfhost.monitoring.enable
Example:
true
Declared by:
selfhost.services.<name>.integrations.monitoring.exporters
Custom Prometheus exporters for this service
Type: attribute set of anything
Default:
{ }
Declared by:
selfhost.services.<name>.integrations.monitoring.healthcheck
Whether to auto-generate a blackbox healthcheck probe for this service
Type: boolean
Default:
true
Declared by:
selfhost.services.<name>.integrations.monitoring.rules
Custom Prometheus alert rule groups
Type: list of (attribute set)
Default:
[ ]
Declared by:
selfhost.services.<name>.integrations.monitoring.scrapeConfigs
Custom Prometheus scrape configurations
Type: list of (attribute set)
Default:
[ ]
Declared by:
selfhost.services.<name>.integrations.monitoring.systemdOverrides
Systemd service overrides for monitoring-related units
Type: attribute set of anything
Default:
{ }
Declared by:
selfhost.services.<name>.integrations.notify
notification integration
Type: submodule
Default:
{ }
Declared by:
selfhost.services.<name>.integrations.notify.enable
Publish notifications for this service/task.
Type: boolean
Default:
on when a notify provider is active and topic is set
Declared by:
selfhost.services.<name>.integrations.notify.tokenFile
Path to this publisher’s access token, provisioned root-owned 0400. How a publisher reads it
depends on its user:
- runs as root (e.g. backup, task failure-hooks): read this path directly, at send time. Best-effort — no dependency on the provider being up, so notify never blocks the publisher.
- runs as a non-root user (e.g. transmission): receive it via systemd
LoadCredential = [ "notify-token:${...tokenFile}" ]and read%d/notify-token($CREDENTIALS_DIRECTORY/notify-token). Because LoadCredential reads the source at unit start, order the unitafterthe provider’s provisioning unit (selfhost.notify.provisioningUnit).
Type: string (read only)
Default:
"/var/lib/homelab-secrets/notify-publishers/‹name›"
Declared by:
selfhost.services.<name>.integrations.notify.topic
Notification topic this service/task publishes to (null = none).
Type: null or impossible (empty enum)
Default:
null
Declared by:
selfhost.services.<name>.meta.category
Canonical grouping key; a consumer surface (e.g. a landing page) groups services by this.
Type: null or string
Default:
null
Declared by:
selfhost.services.<name>.meta.description
Short description (nixpkgs meta.description).
Type: string
Declared by:
selfhost.services.<name>.meta.homepage
Upstream project homepage (nixpkgs meta.homepage).
Type: null or string
Default:
null
Declared by:
selfhost.services.<name>.name
Registry identifier (defaults to attribute name)
Type: string
Default:
"‹name›"
Declared by:
selfhost.services.<name>.oidc
OIDC client configuration for this service
Type: submodule
Default:
{ }
Declared by:
selfhost.services.<name>.oidc.enable
Whether to enable OIDC client for this service.
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.services.<name>.oidc.callbackURLs
Callback URLs for the OIDC client
Type: list of string
Default:
[ <publicUrl>/oauth2/oidc/callback ]
Declared by:
selfhost.services.<name>.oidc.gid
Fixed GID for the credentials group (null = auto-assign)
Type: null or signed integer
Default:
null
Declared by:
selfhost.services.<name>.oidc.group
Group name for this client’s credentials
Type: string (read only)
Default:
"homelab-oidc-‹name›"
Declared by:
selfhost.services.<name>.oidc.id.file
Path to the file containing the client ID
Type: string (read only)
Default:
"/var/lib/homelab-oidc/‹name›/id"
Declared by:
selfhost.services.<name>.oidc.id.placeholder
Placeholder for client ID (use in config files, substituted at runtime)
Type: string (read only)
Default:
"@HOMELAB_OIDC_‹name›_ID@"
Declared by:
selfhost.services.<name>.oidc.name
Display name of the OIDC client in the provider
Type: string
Default:
"‹name›"
Declared by:
selfhost.services.<name>.oidc.pkce
Enable PKCE for this client
Type: boolean
Default:
false
Declared by:
selfhost.services.<name>.oidc.secret.file
Path to the file containing the client secret
Type: string (read only)
Default:
"/var/lib/homelab-oidc/‹name›/secret"
Declared by:
selfhost.services.<name>.oidc.secret.placeholder
Placeholder for client secret (use in config files, substituted at runtime)
Type: string (read only)
Default:
"@HOMELAB_OIDC_‹name›_SECRET@"
Declared by:
selfhost.services.<name>.oidc.systemd.dependentServices
Systemd services needing this client’s credentials; auto-wired requires/after/partOf.
Type: list of string
Default:
[ ]
Declared by:
selfhost.services.<name>.oidc.systemd.loadCredentials
Ready-to-use LoadCredential entries for systemd services
Type: list of string (read only)
Default:
[
"oidc-id:/var/lib/homelab-oidc/‹name›/id"
"oidc-secret:/var/lib/homelab-oidc/‹name›/secret"
]
Declared by:
selfhost.services.<name>.oidc.systemd.supplementaryGroups
Groups to add for direct credential file access
Type: list of string (read only)
Default:
[
"homelab-oidc-‹name›"
]
Declared by:
selfhost.services.<name>.port
Port the service listens on
Type: 16 bit unsigned integer; between 0 and 65535 (both inclusive)
Declared by:
selfhost.services.<name>.publicHost
Public hostname (derived from subdomain and ingress.domain)
Type: string
Default:
<subdomain>.<ingress.domain>
Declared by:
selfhost.services.<name>.publicUrl
Full public URL (derived from publicHost)
Type: string
Default:
https://<publicHost>
Declared by:
selfhost.services.<name>.scheme
URL scheme for backend connection
Type: one of “http”, “https”
Default:
"http"
Declared by:
selfhost.services.<name>.storage.mounts
Named selfhost SMB shares this service may access; their automount guards start before the service.
Type: list of impossible (empty enum)
Default:
[ ]
Declared by:
selfhost.services.<name>.storage.systemdServices
Systemd service names to guard instead of the inferred service or OCI-container name.
Type: list of string
Default:
[ ]
Declared by:
selfhost.services.<name>.subdomain
Subdomain prefix (combined with domain for publicHost)
Type: string
Default:
"‹name›"
Declared by:
selfhost.services.<name>.traefik.middlewares
Extra Traefik middleware definitions to attach to this service’s router
Type: attribute set of attribute set of unspecified value
Default:
{ }
Declared by:
selfhost.services.<name>.url
Full URL for proxying (derived from scheme, host and port)
Type: string
Default:
<scheme>://<host>:<port>
Declared by:
selfhost.storage.mounts.smb.enable
Whether to enable Home-server storage.
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.storage.mounts.smb.credentialsPath
Path to the SMB credentials file (must be provided by the host, e.g. via sops-nix)
Type: string
Declared by:
selfhost.storage.mounts.smb.hostname
IP or hostname of the SMB server; prefer an IP or /etc/hosts entry for reliable resolution at boot.
Type: string
Declared by:
selfhost.storage.mounts.smb.shares
CIFS shares keyed by remote root folder, each behind a dedicated access group and mounted on demand. Boot does not wait for the SMB server. First access may wait up to 30 seconds; after a failed mount, a later access retries.
Type: attribute set of (submodule)
Default:
{ }
Example:
{
bphenriques = { };
media = { };
}
Declared by:
selfhost.storage.mounts.smb.shares.<name>.gid
GID for the mount group (required for SMB mount options)
Type: signed integer
Declared by:
selfhost.storage.mounts.smb.shares.<name>.group
Name of the group with access to the mount
Type: string
Default:
"homelab-‹name›"
Declared by:
selfhost.storage.mounts.smb.shares.<name>.localMount
Local mount point for the share
Type: string
Default:
"/mnt/homelab-‹name›"
Declared by:
selfhost.storage.mounts.smb.shares.<name>.systemd.dependentServices
Extra systemd service names to order after this share’s automount guard.
Type: list of string
Default:
[ ]
Declared by:
selfhost.storage.mounts.smb.shares.<name>.uid
File-owner UID on the client (default 0/root → access via group; set per-user for owner-level ops like chmod/git).
Type: signed integer
Default:
0
Declared by:
selfhost.tasks
Registry of externally-defined systemd units that opt into selfhost concerns (notify, storage).
Type: attribute set of (submodule)
Default:
{ }
Declared by:
selfhost.tasks.<name>.integrations.notify
notification integration
Type: submodule
Default:
{ }
Declared by:
selfhost.tasks.<name>.integrations.notify.enable
Publish notifications for this service/task.
Type: boolean
Default:
on when a notify provider is active and topic is set
Declared by:
selfhost.tasks.<name>.integrations.notify.tokenFile
Path to this publisher’s access token, provisioned root-owned 0400. How a publisher reads it
depends on its user:
- runs as root (e.g. backup, task failure-hooks): read this path directly, at send time. Best-effort — no dependency on the provider being up, so notify never blocks the publisher.
- runs as a non-root user (e.g. transmission): receive it via systemd
LoadCredential = [ "notify-token:${...tokenFile}" ]and read%d/notify-token($CREDENTIALS_DIRECTORY/notify-token). Because LoadCredential reads the source at unit start, order the unitafterthe provider’s provisioning unit (selfhost.notify.provisioningUnit).
Type: string (read only)
Default:
"/var/lib/homelab-secrets/notify-publishers/‹name›"
Declared by:
selfhost.tasks.<name>.integrations.notify.topic
Notification topic this service/task publishes to (null = none).
Type: null or impossible (empty enum)
Default:
null
Declared by:
selfhost.tasks.<name>.name
Task identifier (defaults to the attribute name).
Type: string
Default:
"‹name›"
Declared by:
selfhost.tasks.<name>.storage.mounts
Named selfhost SMB shares this task may access; their automount guards start before the task.
Type: list of impossible (empty enum)
Default:
[ ]
Declared by:
selfhost.tasks.<name>.systemdServices
Systemd units this task owns; selfhost concerns attach to them.
Type: (list of string) or string convertible to it
Default:
[ ]
Declared by:
selfhost.users
This option has no description.
Type: attribute set of (submodule)
Default:
{ }
Declared by:
- modules/nixos/services/wireguard/user.nix
- modules/nixos/services/radicale/user.nix
- modules/nixos/services/miniflux/user.nix
- modules/nixos/services/jellyfin/user.nix
- modules/nixos/services/immich/user.nix
- modules/nixos/services/gitea/user.nix
- modules/nixos/services/filebrowser/selfhost.nix
- modules/nixos/users.nix
selfhost.users.<name>.auth.oidc.enable
Whether to enable OIDC account for this user.
Type: boolean
Default:
true
Example:
true
Declared by:
selfhost.users.<name>.email
This option has no description.
Type: string
Declared by:
selfhost.users.<name>.extraConfig
Consumer-owned per-user data with no first-class option; selfhost-nix never reads it. Per-service config mirrors the registry at users.<name>.services.<name>, not here. Read back at config.selfhost.users.<name>.extraConfig.
Type: open submodule of attribute set of anything
Default:
{ }
Declared by:
selfhost.users.<name>.firstName
This option has no description.
Type: string
Declared by:
selfhost.users.<name>.groups
Groups assigned to this user. If admin group is included, the user is marked as admin.
Type: list of string
Default:
[ ]
Declared by:
selfhost.users.<name>.isAdmin
This option has no description.
Type: boolean (read only)
Default:
true if the user’s groups include the admin group
Declared by:
selfhost.users.<name>.lastName
This option has no description.
Type: string
Declared by:
selfhost.users.<name>.name
This option has no description.
Type: string
Default:
<firstName> <lastName>
Declared by:
selfhost.users.<name>.services.filebrowser.enable
Whether to enable a FileBrowser entry for this user (access is gated by the service auth, not this flag).
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.users.<name>.services.filebrowser.admin
Whether to enable FileBrowser admin.
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.users.<name>.services.filebrowser.storage
selfhost SMB mounts this user may access, keyed by permission; unioned into their scope (read-write iff any is rw).
Type: attribute set of (one of “ro”, “rw”)
Default:
{ }
Declared by:
selfhost.users.<name>.services.gitea.enable
Whether to enable a Gitea account for this user.
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.users.<name>.services.gitea.admin
Gitea site-admin (reconciled each run); defaults to the user’s fleet isAdmin.
Type: boolean
Default:
false
Declared by:
selfhost.users.<name>.services.immich.enable
Whether to enable an Immich account for this user.
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.users.<name>.services.immich.admin
Grant this account Immich administrator rights.
Type: boolean
Default:
the user’s isAdmin
Declared by:
selfhost.users.<name>.services.immich.libraries
External libraries owned by this user: existing directories Immich scans in place. Empty leaves the account upload-only, which is the common case.
Type: list of (submodule)
Default:
[ ]
Declared by:
selfhost.users.<name>.services.immich.libraries.*.exclusionPatterns
Glob patterns skipped during the scan.
Type: list of string
Default:
[ ]
Declared by:
selfhost.users.<name>.services.immich.libraries.*.importPaths
Directories Immich scans for this library. The app grants the service write access to them.
Type: list of string
Default:
[ ]
Declared by:
selfhost.users.<name>.services.immich.libraries.*.name
Library name as shown in Immich; also its reconcile identity, so renaming creates a new one.
Type: string
Declared by:
selfhost.users.<name>.services.immich.passwordFile
Path to a file holding the initial password, applied at account creation and never reconciled. Null generates a random one, for accounts that sign in through OIDC.
Type: null or string
Default:
null
Declared by:
selfhost.users.<name>.services.immich.quotaBytes
Upload quota for this account in bytes. Null is unlimited. Reconciled, so changing it moves the existing account’s quota.
Type: null or (unsigned integer, meaning >=0)
Default:
null
Example:
107374182400
Declared by:
selfhost.users.<name>.services.immich.storageLabel
Folder name for this account under a {{label}} storage template. Null falls back to the account’s UUID. Reconciled.
Type: null or string
Default:
null
Declared by:
selfhost.users.<name>.services.jellyfin.enable
Whether to enable a Jellyfin account for this user.
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.users.<name>.services.jellyfin.passwordFile
Path to a file holding the initial password, applied at account creation and never reconciled. Null generates a random one.
Type: null or string
Default:
null
Declared by:
selfhost.users.<name>.services.jellyfin.policy
Fields merged into this account’s Jellyfin UserPolicy on every run, applied verbatim. Anything not named here keeps whatever Jellyfin holds.
Type: attribute set of anything
Default:
{ }
Example:
{
EnableSubtitleManagement = true;
IsHidden = false;
}
Declared by:
selfhost.users.<name>.services.miniflux.settings
Per-user Miniflux preferences, applied verbatim via the user-update API (is_admin is framework-managed and ignored here).
Type: attribute set of anything
Default:
{ }
Example:
{
display_mode = "fullscreen";
theme = "dark_serif";
}
Declared by:
selfhost.users.<name>.services.radicale.enable
Whether to enable Radicale CalDAV/CardDAV access for this user.
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.users.<name>.services.wireguard.enable
Whether to enable WireGuard configuration for this user.
Type: boolean
Default:
false
Example:
true
Declared by:
selfhost.users.<name>.services.wireguard.devices
WireGuard devices for this user.
Type: list of (submodule)
Default:
[ ]
Declared by:
selfhost.users.<name>.services.wireguard.devices.*.fullAccess
If true, device can reach the whole LAN; if false, only the home server.
Type: boolean
Default:
false
Declared by:
selfhost.users.<name>.services.wireguard.devices.*.ip
Static WireGuard client IP (e.g. 10.100.0.42).
Type: string
Declared by:
selfhost.users.<name>.services.wireguard.devices.*.name
Device name (e.g. phone, laptop). Lowercase alphanumeric and dashes only.
Type: string matching the pattern [a-z0-9][a-z0-9-]*
Declared by:
selfhost.users.<name>.services.wireguard.devices.*.publicKey
Device’s WireGuard public key, from wg-manage add (the private key stays on the server).
Type: string
Declared by:
selfhost.users.<name>.username
This option has no description.
Type: string
Default:
"‹name›"
Declared by: